Anomaly detection method, apparatus, device and medium for internet of things device
By constructing a target dataset and utilizing basis function expansion and error square integral methods, the problems of low accuracy and high false alarm rate in anomaly detection of IoT devices are solved, achieving more efficient anomaly detection.
Patent Information
- Application Number
- CN202111625014.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-28
- Publication Date
- 2025-11-07
- Estimated Expiration
- 2041-12-28
AI Technical Summary
Existing technologies for detecting anomalies in IoT devices have low accuracy and high false alarm rates, making it difficult to effectively identify abnormal situations.
By constructing a target dataset, using the basis function expansion method and functional principal component analysis, combined with the error square integral method, a data anomaly detection formula is built to determine whether IoT devices are abnormal.
It improved the detection accuracy of the IoT platform, reduced the false alarm rate, and improved the accuracy of anomaly detection.
Smart Images

Figure CN114356705B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of Internet of Things, and in particular to an anomaly detection method and device for Internet of Things equipment, an equipment and a medium. BACKGROUND
[0002] With the development of Internet of Things technology, Internet of Things equipment has shown explosive growth, but due to the characteristics of small size, low power consumption and limited resources, it is difficult to program and interact, and the deployment place is generally remote, which is easily attacked by various attacks, so that the Internet of Things equipment runs abnormally. In the prior art, the anomaly detection of Internet of Things equipment mainly detects the data collected by the Internet of Things equipment, and at present, the collected data is mainly detected based on statistical, distance, density and pattern recognition methods, but the detection accuracy is low and the false positive rate is high. SUMMARY
[0003] The embodiments of the present application provide an anomaly detection method, device, equipment and medium for Internet of Things equipment, aiming to improve the detection accuracy of the Internet of Things platform and reduce the false positive rate.
[0004] In a first aspect, the embodiments of the present application provide an anomaly detection method for Internet of Things equipment, which comprises:
[0005] If a preset data detection instruction is received, multi-dimensional collection data uploaded by the Internet of Things equipment in a preset time period is obtained from a preset database according to the preset data detection instruction, and a target data set is constructed according to the multi-dimensional collection data, wherein the multi-dimensional collection data is data collected by a plurality of sensors built-in the Internet of Things equipment;
[0006] A linear combination function is constructed by a basis function expansion method according to the target data set and a preset basis function;
[0007] A function type principal component analysis is performed on the linear combination function to obtain an anomaly detection target function;
[0008] A data anomaly detection formula is constructed by an error square integral method according to the anomaly detection target function and the target data set;
[0009] Data in the target data set is detected by the data anomaly detection formula according to a preset error square integral mean to obtain a detection result, wherein the detection result is used to judge whether the Internet of Things equipment is abnormal.
[0010] In a second aspect, the embodiments of the present application further provide an anomaly detection device for Internet of Things equipment, which comprises:
[0011] The first construction unit is configured to, if a preset data detection instruction is received, acquire multi-dimensional collection data uploaded by the Internet of Things device in a preset time period from a preset database according to the preset data detection instruction, and construct a target data set according to the multi-dimensional collection data, wherein the multi-dimensional collection data is data collected by a plurality of sensors built in the Internet of Things device.
[0012] The second construction unit is configured to construct a linear combination function by a base function expansion method according to the target data set and a preset base function.
[0013] The analysis unit is configured to perform a functional principal component analysis on the linear combination function to obtain an anomaly detection target function.
[0014] The third construction unit is configured to construct a data anomaly detection formula by an error square integral method according to the anomaly detection target function and the target data set.
[0015] The detection unit is configured to detect data in the target data set by the data anomaly detection formula according to a preset error square integral mean to obtain a detection result, wherein the detection result is used to judge whether the Internet of Things device is abnormal.
[0016] In a third aspect, an embodiment of the present application further provides a computer device, which comprises a memory and a processor, the memory has a computer program stored thereon, and the processor implements the above method when executing the computer program.
[0017] In a fourth aspect, an embodiment of the present application further provides a computer readable storage medium, the storage medium has a computer program stored thereon, and the computer program can implement the above method when being executed by a processor.
[0018] The embodiment of the present application provides an anomaly detection method, device and equipment for an Internet of Things device and a medium. The method comprises the following steps: if a preset data detection instruction is received, acquiring multi-dimensional collection data uploaded by an Internet of Things device in a preset time period from a preset database according to the preset data detection instruction, and constructing a target data set according to the multi-dimensional collection data, wherein the multi-dimensional collection data is data collected by a plurality of sensors built in the Internet of Things device; constructing a linear combination function by a base function expansion method according to the target data set and a preset base function; performing function type principal component analysis on the linear combination function to obtain an anomaly detection target function; constructing a data anomaly detection formula by an error square integral method according to the anomaly detection target function and the target data set; and detecting data in the target data set by the data anomaly detection formula according to a preset error square integral mean to obtain a detection result, wherein the detection result is used to judge whether the Internet of Things device is abnormal. The technical scheme of the embodiment of the present application can improve the detection accuracy of an Internet of Things platform and reduce the false positive rate. BRIEF DESCRIPTION OF DRAWINGS
[0019] In order to more clearly illustrate the technical scheme in the embodiments of the present application, the drawings needed in the embodiment description will be briefly introduced. Obviously, the drawings in the following description are some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.
[0020] Figure 1 A flowchart of an anomaly detection method for an Internet of Things device provided by the embodiment of the present application is shown in the figure.
[0021] Figure 2 A schematic block diagram of an anomaly detection device for an Internet of Things device provided by the embodiment of the present application is shown in the figure.
[0022] Figure 3 A schematic block diagram of a computer device provided by the embodiment of the present application is shown in the figure. DETAILED DESCRIPTION
[0023] The technical scheme in the embodiments of the present application will be described clearly and completely in combination with the drawings in the embodiments of the present application. Obviously, the described embodiments are some embodiments of the present application, but not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the protection scope of the present application.
[0024] It should be understood that the terms "comprises" and "comprising" when used in this specification and accompanying claims, signify the presence of the stated features, integers, steps, operations, elements, and / or components but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.
[0025] It should also be understood that the terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of the present application. As used in this specification and the appended claims, the singular forms "a," "an" and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise.
[0026] It will be further understood that the terms "and / or," as used herein, refers to and encompasses any and all possible combinations of one or more of the associated listed items, and that the term "at least one of' encompasses one or more items.
[0027] As used in this specification and the appended claims, the term "if' can be construed to mean "when" or "once," or "in response to a determination" or "in response to the occurrence of an event" depending on the context. Similarly, the phrase "if it is determined" or "if [a described condition or event] is detected" can be construed to mean "once it is determined" or "in response to a determination" or "once [the described condition or event] is detected" or "in response to the detection of [the described condition or event]," depending on the context.
[0028] Referring now to the drawings Figure 1 , Figure 1 is a flowchart of an anomaly detection method for an Internet of Things device provided by an embodiment of the present application. The anomaly detection method for an Internet of Things device of the present embodiment can be applied to an Internet of Things platform, for example, the anomaly detection method for an Internet of Things device can be implemented by a software program configured on the Internet of Things platform, thereby improving the detection accuracy and reducing the false positive rate of the Internet of Things platform. As shown in Figure 1 , the method comprises the following steps S100-S140.
[0029] S100, if a preset data detection instruction is received, acquiring multi-dimensional collection data uploaded by an Internet of Things device in a preset time period from a preset database according to the preset data detection instruction, and constructing a target data set according to the multi-dimensional collection data, wherein the multi-dimensional collection data is data collected by a plurality of sensors built in the Internet of Things device.
[0030] In the embodiment of the present application, the Internet of Things platform receives multi-dimensional collection data uploaded by the Internet of Things device, and saves the multi-dimensional collection data into a preset database corresponding to the Internet of Things platform, wherein the multi-dimensional collection data is data collected by a plurality of sensors built-in the Internet of Things device. When the timing detection time set by the Internet of Things platform arrives, the sending of a preset data detection instruction is triggered, and the Internet of Things platform acquires the multi-dimensional collection data uploaded by the Internet of Things device in a preset time period from the preset database according to the preset data detection instruction, wherein the preset time period is a self-set time period, for example, 24 hours. After the Internet of Things platform acquires the multi-dimensional collection data, a target data set is constructed according to the multi-dimensional collection data. Specifically, the multi-dimensional collection data is divided according to a preset division time to obtain a plurality of data sets, wherein the preset division time is less than the preset time period, for example, 6 hours. Then, each data set is divided into a plurality of sub-data sets according to a preset sensor identifier to obtain a target data set. Understandably, the target data set includes a plurality of data sets, and each data set includes a plurality of sub-data sets.
[0031] S110, constructing a linear combination function by a basis function expansion method according to the target data set and a preset basis function.
[0032] In the embodiment of the present application, after the target data set is constructed according to the multi-dimensional collection data, a linear combination function is constructed by a basis function expansion method according to the target data set and a preset basis function. Specifically, it is first judged whether the target data set is a data set with periodic characteristics. If the target data set is a data set with periodic characteristics, it indicates that the data curvature in the target data set is similar, and then a linear combination function is constructed by a basis function expansion method according to a Fourier basis function and a preset coefficient, wherein the preset coefficient can be self-set according to requirements. The first basis function expansion method is to use the Fourier basis function and the preset coefficient to calculate a fitting estimated collection value. If the target data set is a data set without periodic characteristics, it indicates that the data of the target data set has local characteristics, and then the linear combination function is constructed by a second basis function expansion method according to a B-spline basis function and the preset coefficient, wherein the second basis function expansion method is to use the B-spline basis function and the preset coefficient to calculate a fitting estimated value collection value. It should be noted that in the embodiment of the present application, discrete data can be expressed by a function smoothing method by the basis function expansion method.
[0033] S120, performing function principal component analysis on the linear combination function to obtain an anomaly detection target function.
[0034] In the embodiment of the present application, after the linear combination function is constructed by the base function expansion method, the function type principal component analysis is performed on the linear combination function to obtain an anomaly detection target function, wherein the anomaly detection target function is a principal component score function. Specifically, the preset principal component weight function and the linear combination function are substituted into the preset function type principal component formula to obtain the anomaly detection target function, wherein the anomaly detection target function is wherein β(t) is a preset principal component weight function, x i (t) is the linear combination function, and a and b are respectively the start time and the end time of a preset time period. It should be noted that in the embodiment of the present application, the function type principal component analysis is performed on the linear combination function in order to reduce the dimension of the linear combination function, thereby obtaining a simplified anomaly detection target function.
[0035] In the embodiment of the present application, after the linear combination function is constructed by the base function expansion method, the function type principal component analysis is performed on the linear combination function to obtain an anomaly detection target function, wherein the anomaly detection target function is a principal component score function. Specifically, the preset principal component weight function and the linear combination function are substituted into the preset function type principal component formula to obtain the anomaly detection target function, wherein the anomaly detection target function is
[0036] In the embodiment of the present application, after the linear combination function is constructed by the base function expansion method, the function type principal component analysis is performed on the linear combination function to obtain an anomaly detection target function, wherein the anomaly detection target function is a principal component score function. Specifically, the preset principal component weight function and the linear combination function are substituted into the preset function type principal component formula to obtain the anomaly detection target function, wherein the anomaly detection target function is i 2 (t), and the target data set is y i (t), the difference value square sum formula is a formula for squaring the difference value between the target data set and the anomaly detection target function; and the difference value square sum formula is substituted into the preset integral formula to obtain the data anomaly detection formula, wherein the preset integral formula is The data anomaly detection formula V i (t) is shown in formula (1):
[0037]
[0038] It should be noted that K in formula (1) is the number of principal components, and the number of principal components can be determined by the gravel map method and the cumulative variance interpretation ratio method.
[0039] In the embodiment of the present application, after the linear combination function is constructed by the base function expansion method, the function type principal component analysis is performed on the linear combination function to obtain an anomaly detection target function, wherein the anomaly detection target function is a principal component score function. Specifically, the preset principal component weight function and the linear combination function are substituted into the preset function type principal component formula to obtain the anomaly detection target function, wherein the anomaly detection target function is
[0040] In the embodiment of the present application, after the data anomaly detection formula is constructed by the error square integral method, the error square integral value corresponding to the current sub-data set in the current data set is calculated by the data anomaly detection formula; if the error square integral value is not greater than the preset error square integral mean value, it indicates that the collected data in the current sub-data set is normal data, i.e., it indicates that the Internet of Things device is running normally in the time period corresponding to the current data set, and there is no need to detect the collected data in other data sets, then the current data set is put into the preset sample library; the current error square integral mean value is calculated by the data anomaly detection formula according to the preset sample library, and the current error square integral mean value is taken as the preset error square integral mean value to update the preset error square integral mean value, so that the detection is more accurate; the next data set is taken as the current data set, and the step of calculating the error square integral value corresponding to the current sub-data set in the current data set by the data anomaly detection formula is returned until all the data sets are detected, at this time, the detection result is set to normal detection, indicating that the Internet of Things device is running normally in the preset time period. Understandably, if the error square integral value is greater than the preset error square integral mean value, it indicates that the collected data in the current sub-data set is abnormal, in order to detect more accurately, the next sub-data set is taken as the current sub-data set, and the step of calculating the error square integral value corresponding to the current sub-data set in the current data set by the data anomaly detection formula is returned to detect other sub-data sets in the current data set until all the sub-data sets in the current data set are detected. In actual application, in the time period corresponding to the current data, if it is detected that the data collected by the current sensor is abnormal, in order to detect more accurately, the data collected by other sensors will be detected again for comprehensive judgment to improve the detection accuracy of the Internet of Things platform and reduce the false alarm rate. It should be noted that in the embodiment of the present application, if it is detected that the data collected by other sensors is also abnormal, the detection result is set to abnormal detection, and an alarm prompt is sent to remind the relevant personnel to check the log of the Internet of Things device.
[0041] Figure 2 is a schematic block diagram of an anomaly detection device 200 for an Internet of Things device provided by the embodiment of the present application. As shown in Figure 2 corresponding to the above anomaly detection method for an Internet of Things device, the present application also provides an anomaly detection device 200 for an Internet of Things device. The anomaly detection device 200 for an Internet of Things device comprises units for executing the above anomaly detection method for an Internet of Things device. Specifically, please refer to Figure 2 , the anomaly detection device 200 for an Internet of Things device comprises a first construction unit 201, a second construction unit 202, an analysis unit 203, a third construction unit 204, and a detection unit 205.
[0042] The first construction unit 201 is configured to, if a preset data detection instruction is received, acquire multi-dimensional collection data uploaded by an Internet of Things device in a preset time period from a preset database according to the preset data detection instruction, and construct a target data set according to the multi-dimensional collection data, wherein the multi-dimensional collection data is data collected by a plurality of sensors built in the Internet of Things device; the second construction unit 202 is configured to construct a linear combination function by a basis function expansion method according to the target data set and a preset basis function; the analysis unit 203 is configured to perform functional principal component analysis on the linear combination function to obtain an anomaly detection target function; the third construction unit 204 is configured to construct a data anomaly detection formula by an error square integral method according to the anomaly detection target function and the target data set; and the detection unit 205 is configured to detect data in the target data set by the data anomaly detection formula according to a preset error square integral mean to obtain a detection result, wherein the detection result is used to judge whether the Internet of Things device is abnormal.
[0043] In some embodiments, for example in the present embodiment, the first construction unit 201 comprises a first division unit 2011 and a second division unit 2012.
[0044] The first division unit 2011 is configured to divide the multi-dimensional collection data according to a preset division time to obtain a plurality of data sets; and the second division unit 2012 is configured to divide each of the data sets into a plurality of sub-data sets according to a preset sensor identifier to obtain a target data set.
[0045] In some embodiments, for example in the present embodiment, the second construction unit 202 comprises a first construction sub-unit 2021 and a second construction sub-unit 2022.
[0046] The first construction sub-unit 2021 is configured to, if the target data set is a data set with periodic characteristics, construct a linear combination function by a first basis function expansion method according to a Fourier basis function and a preset coefficient; and the second construction sub-unit 2022 is configured to, if the target data set is a data set without periodic characteristics, construct the linear combination function by a second basis function expansion method according to a B-spline basis function and the preset coefficient.
[0047] In some embodiments, for example in the present embodiment, the third construction unit 204 comprises a first substitution unit 2041 and a second substitution unit 2042.
[0048] The first substitution unit 2041 is configured to substitute the target data set and the anomaly detection target function into a preset sum of squares formula to obtain a difference sum of squares formula; and the second substitution unit 2042 is configured to substitute the difference sum of squares formula into a preset integral formula to obtain a data anomaly detection formula.
[0049] In some embodiments, for example in the present embodiment, the detection unit 205 includes a first calculation unit 2051, a second calculation unit 2052, a first return execution unit 2053, and a second return execution unit 2054.
[0050] The first calculation unit 2051 is configured to calculate, by using the data anomaly detection formula, an error square integral value corresponding to a current sub-data set in a current data set; the second calculation unit 2052 is configured to, if the error square integral value is not greater than a preset error square integral mean value, put the current data set into a preset sample library, calculate a current error square integral mean value by using the data anomaly detection formula according to the preset sample library, and take the current error square integral mean value as the preset error square integral mean value; the return execution unit 2053 is configured to take a next data set as the current data set, and return the step of calculating, by using the data anomaly detection formula, the error square integral value corresponding to the current sub-data set in the current data set until all the data sets are detected, to obtain a detection result; and the second return execution unit 2054 is configured to, if the error square integral value is greater than the preset error square integral mean value, take a next sub-data set as the current sub-data set, and return the step of calculating, by using the data anomaly detection formula, the error square integral value corresponding to the current sub-data set in the current data set until all the sub-data sets in the current data set are detected, to obtain the detection result.
[0051] In some embodiments, for example in the present embodiment, the anomaly detection apparatus 200 further includes a prompt unit 206.
[0052] The prompt unit 206 is configured to, if the detection result is an abnormality, issue an alarm prompt to remind relevant personnel to recheck logs of the Internet of Things device.
[0053] It should be noted that the specific implementation process of the anomaly detection apparatus 200 for the Internet of Things device and each unit can be clearly understood by those skilled in the art, which can be referred to the corresponding description in the foregoing method embodiments. For the convenience and brevity of description, it will not be described here.
[0054] The anomaly detection apparatus for the Internet of Things device can be implemented in the form of a computer program, which can run on a computer device as shown in Figure 3 .
[0055] Please refer to Figure 3 , Figure 3 is a schematic block diagram of a computer device provided by an embodiment of the present application. The computer device 900 is a server with an Internet of Things platform.
[0056] Please refer to Figure 3 , the computer device 900 includes a processor 902, a memory and an interface 907 connected through a system bus 901, wherein the memory can include a storage medium 903 and an internal memory 904.
[0057] The storage medium 903 can store an operating system 9031 and a computer program 9032. The computer program 9032, when executed, can cause the processor 902 to perform the above-mentioned abnormality detection method for an Internet of Things device.
[0058] The processor 902 is configured to provide computing and control capabilities to support the operation of the entire computer device 900.
[0059] The internal memory 904 provides an environment for the execution of the computer program 9032 in the storage medium 903, and the computer program 9032, when executed by the processor 902, can cause the processor 902 to perform an abnormality detection method for an Internet of Things device.
[0060] The interface 905 is configured to communicate with other devices. Those skilled in the art can understand that Figure 3 The structure shown in the figure is only a block diagram of part of the structure related to the scheme of the present application, and does not constitute a limitation on the computer device 900 to which the scheme of the present application is applied. The specific computer device 900 can include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.
[0061] The processor 902 is configured to run the computer program 9032 stored in the memory to implement the following steps: if a preset data detection instruction is received, obtaining multi-dimensional collection data uploaded by an Internet of Things device in a preset time period from a preset database according to the preset data detection instruction, and constructing a target data set according to the multi-dimensional collection data, wherein the multi-dimensional collection data is data collected by a plurality of sensors built in the Internet of Things device; constructing a linear combination function by a basis function expansion method according to the target data set and a preset basis function; performing functional principal component analysis on the linear combination function to obtain an anomaly detection target function; constructing a data anomaly detection formula by an error square integral method according to the anomaly detection target function and the target data set; and detecting data in the target data set by the data anomaly detection formula according to a preset error square integral mean to obtain a detection result, wherein the detection result is used to determine whether the Internet of Things device is abnormal.
[0062] In some embodiments, for example in the present embodiment, when implementing the step of constructing a target data set according to the multi-dimensional collection data, the processor 902 specifically implements the following steps: dividing the multi-dimensional collection data according to a preset division time to obtain a plurality of data sets; and dividing each of the data sets into a plurality of sub-data sets according to a preset sensor identifier to obtain the target data set.
[0063] In some embodiments, for example in the present embodiment, when implementing the step of constructing a linear combination function by a basis function expansion method according to the target data set and a preset basis function, the processor 902 specifically implements the following steps: if the target data set is a data set with periodic characteristics, constructing a linear combination function by a first basis function expansion method according to a Fourier basis function and a preset coefficient; and if the target data set is a data set without periodic characteristics, constructing the linear combination function by a second basis function expansion method according to a B-spline basis function and the preset coefficient.
[0064] In some embodiments, for example in the present embodiment, when implementing the step of constructing a data anomaly detection formula by an error square integral method according to the anomaly detection target function and the target data set, the processor 902 specifically implements the following steps: substituting the target data set and the anomaly detection target function into a preset sum of squares formula to obtain a difference sum of squares formula; and substituting the difference sum of squares formula into a preset integral formula to obtain the data anomaly detection formula.
[0065] In some embodiments, such as the present embodiment, the processor 902, when implementing the step of detecting data in the target data set according to the preset error square integral average through the data anomaly detection formula to obtain a detection result, specifically implements the following steps: calculating an error square integral value corresponding to a current sub-data set in the current data set through the data anomaly detection formula; if the error square integral value is not greater than the preset error square integral average, placing the current data set into a preset sample library, and calculating a current error square integral average through the data anomaly detection formula according to the preset sample library, taking the current error square integral average as the preset error square integral average; taking a next data set as the current data set, and returning to the step of calculating the error square integral value corresponding to the current sub-data set in the current data set through the data anomaly detection formula until all the data sets are detected to obtain the detection result; if the error square integral value is greater than the preset error square integral average, taking a next sub-data set as the current sub-data set, and returning to the step of calculating the error square integral value corresponding to the current sub-data set in the current data set through the data anomaly detection formula until all the sub-data sets in the current data set are detected to obtain the detection result.
[0066] In some embodiments, such as the present embodiment, after the processor 902 implements the step of detecting the multi-dimensional acquisition data according to the preset error square integral average through the data anomaly detection formula to obtain a detection result, the detection result is used to judge whether the Internet of Things device is abnormal, the processor 902 specifically further implements the following steps: if the detection result is an abnormal detection, issuing an alarm prompt to remind relevant personnel to recheck logs of the Internet of Things device.
[0067] It should be understood that, in the embodiments of the present application, the processor 902 can be a central processing unit (CPU), and the processor 902 can also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor.
[0068] Those skilled in the art can understand that all or part of the processes in the method of the above embodiments can be completed by instructing the relevant hardware by a computer program. The computer program can be stored in a storage medium, which is a computer readable storage medium. The computer program is executed by at least one processor in the wireless communication system to implement the process steps of the above method embodiments.
[0069] Therefore, the present application also provides a storage medium. The storage medium can be a computer readable storage medium. The storage medium stores a computer program. The computer program is executed by a processor to make the processor execute any embodiment of the above abnormality detection method for an Internet of Things device.
[0070] The storage medium can be a U disk, a mobile hard disk, a read-only memory (ROM), a magnetic disk or an optical disk, and various computer readable storage media that can store program codes.
[0071] Those skilled in the art can realize that the units and algorithm steps of the examples described in combination with the embodiments disclosed herein can be realized in electronic hardware, wireless communication software or a combination of both. In order to clearly illustrate the interchangeability of hardware and software, the components and steps of the examples have been described in general terms in the above description. Whether the functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. A skilled person can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0072] In several embodiments provided by the present application, it should be understood that the disclosed apparatus and method can be implemented in other ways. For example, the apparatus embodiments described above are merely schematic. For example, the division of each unit is only a logical function division, and actual implementation can have another division manner. For example, a plurality of units or components can be combined or integrated into another system, or some features can be omitted or not executed.
[0073] The steps in the method of the embodiments of the present application can be adjusted, combined and deleted in sequence according to actual needs. The units in the apparatus of the embodiments of the present application can be combined, divided and deleted according to actual needs. In addition, each functional unit in each embodiment of the present application can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit.
[0074] The integrated unit, if implemented in the form of a software function unit and sold or used as an independent product, can be stored in a storage medium. Based on such understanding, the technical solutions of the present application essentially or say the part that contributes to the prior art, or the whole or part of the technical solutions can be embodied in the form of a software product. The wireless communication software product is stored in a storage medium and includes a number of instructions for causing a computer device (which can be a personal wireless communication terminal, a network device, or the like) to execute all or part of the steps of the method described in various embodiments of the present application.
[0075] In the above embodiments, the description of each embodiment has its own focus, and the parts not described in detail in a certain embodiment can be referred to the relevant description of other embodiments.
[0076] Obviously, those skilled in the art can make various modifications and variations to the present application without departing from the spirit and scope of the present application. Thus, these modifications and variations of the present application also belong to the scope of the claims of the present application and its equivalent technologies, and the present application also intends to include these modifications and variations.
[0077] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited to this. Any person skilled in the art can easily think of various equivalent modifications or replacements within the technical range disclosed by the present application, and these modifications or replacements should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. An anomaly detection method for an Internet of Things device, the method comprising: The method comprises the following steps: If a preset data detection instruction is received, multi-dimensional collection data uploaded by an Internet of Things device in a preset time period is obtained from a preset database according to the preset data detection instruction, and a target data set is constructed according to the multi-dimensional collection data, wherein the multi-dimensional collection data is data collected by a plurality of sensors built in the Internet of Things device; A linear combination function is constructed by a basis function expansion method according to the target data set and a preset basis function; Function principal component analysis is performed on the linear combination function to obtain an anomaly detection target function; A data anomaly detection formula is constructed by an error square integral method according to the anomaly detection target function and the target data set; According to a preset error square integral mean, data in the target data set is detected by the data anomaly detection formula to obtain a detection result, wherein the detection result is used to judge whether the Internet of Things device is abnormal; According to a preset error square integral mean, data in the target data set is detected by the data anomaly detection formula to obtain a detection result, wherein the detection result is used to judge whether the Internet of Things device is abnormal; The method comprises the following steps: The multi-dimensional collection data is divided according to a preset division time to obtain a plurality of data sets; Each data set is divided into a plurality of sub-data sets according to a preset sensor identifier to obtain a target data set; The method comprises the following steps: The error square integral value corresponding to the current sub-data set in the current data set is calculated by the data anomaly detection formula; If the error square integral value is not greater than the preset error square integral mean, the current data set is put into a preset sample library, and the current error square integral mean is calculated by the data anomaly detection formula according to the preset sample library, and the current error square integral mean is taken as the preset error square integral mean; 2.The anomaly detection method for an Internet of Things device of claim 1, wherein, The next data set is taken as the current data set, and the step of calculating the error square integral value corresponding to the current sub-data set in the current data set by the data anomaly detection formula is returned until all the data sets are detected to obtain a detection result. The method comprises the following steps: If the target data set is a data set with periodic characteristics, a linear combination function is constructed by a first basis function expansion method according to a Fourier basis function and a preset coefficient; 3.The anomaly detection method for an Internet of Things device of claim 1, wherein, If the target data set is a data set without periodic characteristics, the linear combination function is constructed by a second basis function expansion method according to a B-spline basis function and the preset coefficient. The method comprises the following steps: The target data set and the anomaly detection target function are substituted into a preset square sum formula to obtain a difference square sum formula; 4.The anomaly detection method for an Internet of Things device of claim 1, wherein, The difference square sum formula is substituted into a preset integral formula to obtain a data anomaly detection formula. After the error square integral value corresponding to the current sub-data set in the current data set is calculated by the data anomaly detection formula, the method further comprises the following steps: If the error square integral value is greater than the preset error square integral average value, a next sub-data set is taken as a current sub-data set, and the step of calculating the error square integral value corresponding to the current sub-data set in the current data set by the data anomaly detection formula is executed until all the sub-data sets in the current data set are detected to obtain the detection result. 5.The anomaly detection method for an Internet of Things device of claim 1, wherein, After the detection result is obtained by detecting the multi-dimensional acquisition data according to the preset error square integral average value through the data anomaly detection formula, the method further includes: If the detection result is an anomaly, an alarm prompt is sent to remind relevant personnel to recheck the log of the Internet of Things device.
6. An anomaly detection apparatus for an Internet of Things device, the apparatus comprising: The method includes: If a preset data detection instruction is received, a first construction unit acquires multi-dimensional acquisition data uploaded by the Internet of Things device in a preset time period from a preset database according to the preset data detection instruction, and constructs a target data set according to the multi-dimensional acquisition data, wherein the multi-dimensional acquisition data is data collected by a plurality of sensors built in the Internet of Things device; A second construction unit constructs a linear combination function through a basis function expansion method according to the target data set and a preset basis function; An analysis unit performs function type principal component analysis on the linear combination function to obtain an anomaly detection target function; A third construction unit constructs a data anomaly detection formula through an error square integral method according to the anomaly detection target function and the target data set; A detection unit detects data in the target data set according to a preset error square integral average value through the data anomaly detection formula to obtain a detection result, wherein the detection result is used to determine whether the Internet of Things device is abnormal. The first construction unit includes: A first division unit divides the multi-dimensional acquisition data according to a preset division time to obtain a plurality of data sets; A second division unit divides each data set into a plurality of sub-data sets according to a preset sensor identifier to obtain a target data set; The detection unit includes: A first calculation unit calculates an error square integral value corresponding to a current sub-data set in a current data set through the data anomaly detection formula; A second calculation unit, if the error square integral value is not greater than the preset error square integral average value, puts the current data set into a preset sample library, calculates a current error square integral average value through the data anomaly detection formula according to the preset sample library, and takes the current error square integral average value as the preset error square integral average value; A return execution unit takes a next data set as a current data set, and returns the step of calculating the error square integral value corresponding to the current sub-data set in the current data set through the data anomaly detection formula until all the data sets are detected to obtain a detection result.
7. A computer device, comprising: The computer device is built with an Internet of Things platform, and the computer device includes a memory and a processor, the memory stores a computer program, and the processor executes the computer program to implement the method in any one of claims 1-5. The computer device is built with an Internet of Things platform, and the computer device includes a memory and a processor, the memory stores a computer program, and the processor executes the computer program to implement the method in any one of claims 1-5.
8. A computer-readable storage medium, characterized in that, The storage medium stores a computer program which, when executed by the processor, can implement the method of any one of claims 1-5.
Citation Information
Patent Citations
Internet of Things high-dimensional data anomaly detection method, system and device and medium
CN113807396A
Time series anomaly detection method and apparatus, and computer device and storage medium
WO2021204010A1